IP Library Granted Patent US 10,089,466
Granted Patent B2
US 10,089,466 · App. 15/590,897 · Granted Oct 2, 2018

Real-time network updates for malicious content

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,089,466
App. No.
15/590,897
Granted
Oct 2, 2018
Kind
B2
Abstract

A global response network collects, analyzes, and distributes “cross-vector” threat-related information between security systems to allow for an intelligent, collaborative, and comprehensive real-time response.

Claims (42)

1. A method for identifying network threats, the method comprising:

receiving data over a communication network from one or more real-time data feeds;

aggregating data from a plurality of sources regarding the one or more real-time data feeds;

breaking down the received data from the one or more real-time data feeds into a series of components;

generating reputation scores for each component;

generating a signature based on the received data from at least one of the real-time data feeds;

identifying that the signature is associated with a pattern that has a bad reputation;

identifying that the at least one real-time data feed is associated with malicious content based on a reputation score of a component associated with the identified real-time data feed; and

blocking the identified real-time data feed based on the association with the malicious content and the signature being associated with the pattern that has the bad reputation.

2. The method of claim 1 , wherein at least some of the series of components are thumbprints generated from at least a portion of the at least one real-time data feed.

3. The method of claim 2 , wherein the signature is associated with the malicious content, and at least one thumbprint generated from the at least one real-time data feed is not yet associated with the malicious content, and further comprising associating the at least one thumbprint with the bad reputation.

4. The method of claim 1 , further comprising identifying a component reputation as good or bad for each of the series of components.

5. The method of claim 4 , wherein the component reputation for each of the series of components is identified based on reputation information received from a data center.

6. The method of claim 4 , wherein the component reputation for each of the series of components is identified based on at least one of an IP address, a URL, a file attachment, or an embedded image.

7. The method of claim 4 , further comprising vetting the component reputations identified as good or bad against the data received from a plurality of security appliances using votes received from one or more user devices.

8. A non-transitory computer readable storage medium having embodied thereon a program executable by a processor for implementing a method for identifying network threats, the method comprising:

receiving data over a communication network from one or more real-time data feeds;

aggregating data from a plurality of sources regarding the one or more real-time data feeds;

breaking down the received data from the one or more real-time data feeds into a series of components;

generating reputation scores for each component;

generating a signature based on the received data from at least one of the real-time data feed;

identifying that the signature is associated with a pattern that has a bad reputation;

identifying that the at least one real-time data feed is associated with malicious content based on a reputation score of a component associated with the identified real-time data feed; and

blocking the identified real-time data feed based on the association with the malicious content and the signature being associated with the pattern that has the bad reputation.

9. The non-transitory computer readable storage medium of claim 8 , wherein at least some of the series of components are thumbprints generated from at least a portion of the at least one real-time data feed.

10. The non-transitory computer readable storage medium of claim 9 , wherein the signature is associated with the malicious content, and at least one thumbprint generated from the at least one real-time data feed is not associated with the malicious content, and wherein the program further comprises instructions executable to associate the at least one thumbprint with the bad reputation.

11. The non-transitory computer readable storage medium of claim 8 , wherein the program further comprises instructions executable to identify a component reputation as good or bad for each of the series of components.

12. The non-transitory computer readable storage medium of claim 11 , wherein the component reputation for each of the series of components is identified using reputation information received from a data center.

13. The non-transitory computer readable storage medium of claim 11 , wherein the component reputation for each of the series of components is identified using at least one of an IP address, a URL, a file attachment, or an embedded image.

14. The non-transitory computer readable storage medium of claim 12 , wherein the program further comprises instructions executable to vet the component reputations identified as good or bad against the data received from a plurality of security appliances using votes received from one or more user devices.

15. A system for identifying network threats, the system comprising:

a communication network interface of a computing device that receives data over a communication network from one or more real-time data feeds; and

a memory;

a processor of the computing device that executes instructions stored in the memory, wherein execution of the instructions by the processor:

aggregates data from a plurality of sources regarding the one or more real-time data feeds;

breaks down the received data from the one or more real-time data feeds into a series of components;

generates reputation scores for each component;

generates a signature from the received data from at least one of the real-time data feed;

identifies that the signature is associated with a pattern that has a bad reputation;

identifies that the at least one real-time data feed is associated with malicious content based on a reputation score of a component associated with the identified real-time data feed; and

blocks the identified real-time data feed based on the association with the malicious content and the signature being associated with the pattern that has the bad reputation.

16. The system of claim 15 , further comprising a plurality of security appliances communicatively coupled to the computing device, wherein the component reputations identified as good or bad are vetted against the data received from the plurality of security appliances using votes received from one or more user devices.

Assignments (11)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
CHANGE OF NAME Recorded Jan 2, 2018
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 044985/0732 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2018
From: YANOVSKY, BORIS; EIKENBERRY, SCOTT D; RACHAMREDDY, BHUVANASUNDAR; BILOGORSKIY, NICK; BHIMARAJU, GAYATRI
To: SONICWALL, INC.
Reel/Frame 044519/0606 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2018
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 044985/0771 →
CHANGE OF NAME Recorded Jan 2, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044985/0763 →
MERGER Recorded Jan 2, 2018
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC. C/O THOMA BRAVO, LLC
Reel/Frame 044519/0611 →
CHANGE OF NAME Recorded Jan 2, 2018
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 044519/0616 →
MERGER Recorded Jan 2, 2018
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 044519/0638 →